Skip to content

Release notes for the September, 27 2026 update

Update Version 4.1.202609251551

Extensions

  • Added options in Web RDP sessions operating under command filter control to open a Command Prompt or PowerShell window, or log out of the session, using either the control menu or the /cmd, /ps (/PowerShell), and /exit commands.

  • Added initially hidden StartTLS, Protocol, and Host Name Verification fields to the LDAP Administrator and LDAP HA Administrator asset types to customize LDAP connections used by scripts for password verification, password changes, and account unlocking.

  • Added the Verify Host Name option to the LDAP configuration screen for SSL connections to ensure the connection URL matches the server certificate.

  • Added the Active Directory LDAP Unlock Account and Set Password by Shadow script to the LDAP User asset type.

  • Added the option to disable workflow notifications by selecting the Disabled notification template for approval, approved, or rejected actions on the Workflow Form editing screen.

  • Added Database Driver to perform database maintenance activities using site scripts manipulating database objects as an alternative of connecting directly to the database.

  • Added the Tenant Workflow Selector Report to display the status of all workflow selectors and their relationships with assets and sites.

Security

Components Update

  • Updated application WEB framework to the latest version.

  • Updated database access component to the latest version.

  • Updated terminal emulator to the latest version.

  • Updated dashboard charts component to the latest version.

  • Updated Code Editor component to the latest version.

  • Updated client side markdown component to the latest version.

  • Updated internal scripting language component to the latest version.

  • Updated data management component to the latest version.

  • Updated cryptography module utility component to the latest version.

  • Updated system log connector component to the latest version.

  • Updated WEB HTTP sessions driver to the latest version.

  • Updated client side document sanitation component to the latest version.

  • Updated HTTP communication toolkit to the latest version.

  • Removed the runtime dependency on the Duo Security SDK and replaced it with a native implementation to eliminate dependencies with known vulnerabilities.

  • Removed the runtime dependency on the UTAH Parser and replaced it with a native implementation to eliminate dependencies with known vulnerabilities.

  • Removed the runtime dependency on the Web Console Standard Tag Library and replaced it with a native implementation to eliminate dependencies with known vulnerabilities.

Fixes

  • Fixed the issue with removing duplicated cached users that have collected transit credentials when synchronizing users with the source user directory.

  • Fixed the issue with direct login to the application with Entra ID credentials.

  • Fixed the issue with the visual alignment of long field labels on the asset view screen.

  • Fixed the issue that allowed Site Auditors to unlock asset secrets without the required permissions.

  • Improved the display of request action data in system logs by using readable properties to simplify workflow troubleshooting.

  • Fixed the issue with mass action requests hiding forms that were disabled for unrelated assets in the vault.